ISO/IEC 27001:2022
Certified — inherited Scope · Hosting facility and network (Hetzner Online GmbH)
Hetzner Online GmbH, which provides the dedicated hardware and the data centre the Tessera control plane runs in, operates an information security management system certified to ISO/IEC 27001:2022 by SOCOTEC Certification Deutschland GmbH, with a scope covering all of its hosting services and data centres. Because we run bare metal rather than a managed cloud, what this covers is narrow: the facility, physical access, power, cooling, and network. It says nothing about the operating system upwards, which is ours. Certification of the Tessera entity itself is on the roadmap.
Evidence: Hetzner Online GmbH ISO/IEC 27001:2022 certificate — published by the provider
GDPR (EU 2016/679)
Self-assessed Scope · Tessera as data processor
Tessera acts as a processor for customer content and as a controller for account and billing records. Data protection agreement, records of processing, subprocessor disclosure, and data-subject request handling are in place and self-assessed. No third-party GDPR audit has been performed.
Evidence: DPA available on request · subprocessor list published
CSA CAIQ v4 / STAR Level 1
Self-assessed Scope · Tessera service
Cloud Security Alliance Consensus Assessments Initiative Questionnaire completed as a self-assessment against the Cloud Controls Matrix v4. This is a Level 1 self-attestation, not a third-party (Level 2) certification.
Evidence: Completed CAIQ workbook — available on request
OWASP ASVS 4.0
Aligned — internal Scope · API and web surface — Level 2 target
The Application Security Verification Standard is used as the internal engineering checklist for the API surface. We target Level 2. Verification is internal; there is no external ASVS attestation and no independent penetration test has been completed yet.
Evidence: Internal control mapping
NIST CSF 2.0
Self-assessed Scope · Organisation-wide
Security programme structured against the six NIST Cybersecurity Framework 2.0 functions — Govern, Identify, Protect, Detect, Respond, Recover. Current-profile self-assessment maintained internally with a documented target profile.
Evidence: Current and target profile worksheets
CIS Controls v8.1
Self-assessed Scope · Implementation Group 1, moving to IG2
CIS Critical Security Controls are used for operational hardening baselines — asset inventory, secure configuration, access control management, audit log management, and incident response. Self-assessed at IG1 with IG2 safeguards in progress.
Evidence: CIS-CAT self-assessment worksheet